Skip to content

Accept only reset-password tokens on password update - #319

Open
kaareal wants to merge 2 commits into
masterfrom
security/password-reset-action
Open

kaareal wants to merge 2 commits into
masterfrom
security/password-reset-action

Conversation

@kaareal

@kaareal kaareal commented Sep 24, 2026 •

Copy link
Copy Markdown
Collaborator

Split from #302.

/auth/password/update accepted any access token, including the ones in email unsubscribe links, so a leaked unsubscribe URL could set the password and return a session.

authenticate() now takes an action option and rejects tokens whose action claim doesn't match it with a 401:

  • /auth/password/update requires action: 'reset-password'.
  • /unsubscribe requires action: 'unsubscribe'. A token with the wrong action now gets 401 instead of 400.

Tests that minted reset tokens with action: 'reset' (a value production never issues) now use 'reset-password'.

@github-actions

Copy link
Copy Markdown

API Changes

No changes.

Password update and unsubscribe now declare the action they accept via
authenticate({ type: 'access', action }) instead of checking it in the handler.

Co-Authored-By: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant